
cfn_nag
Linting tool for CloudFormation templates

Linting tool for CloudFormation templates

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security


A list of awesome penetration testing tools and resources.

UT based automated fuzz driver generation

Python Command-Line Ghidra Decompiler

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

RIPS - A static source code analyser for vulnerabilities in PHP scripts

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

Fast code security scanner designed for manual security code review by experts. Outputs line-referenced findings to text files for easy filtering and…

Go static analysis tool that checks for security issues using an AST.

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

👮 👊 RegEx Denial of Service (ReDos) Scanner

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…